Privacy Policy

Last updated: September 24, 2026

Overview

Async Pointing Poker ("we", "our", or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, and safeguard your information when you use our application, particularly in relation to JIRA integration.

JIRA Integration - What We Collect

When you choose to log in with JIRA, we collect only the minimum information necessary to link tickets to your pointing sessions. We do not access, store, or process any information beyond what is required for this specific purpose.

Data Collected from JIRA:

  • Account Information: Your JIRA account ID and email address (used to identify you and link your pointing sessions)
  • JIRA Domain: The domain of your JIRA instance (e.g., your-company.atlassian.net) - required to make API calls to your specific JIRA instance
  • OAuth Tokens: Encrypted access and refresh tokens (stored securely to authenticate API requests on your behalf)
  • Ticket Information: When you import tickets, we only access:
    • Ticket URL (to link tickets to pointing sessions)
    • Ticket title/summary (to display in pointing sessions)
    • Story points (if available, for reference only)

What We Do NOT Collect:

  • Ticket descriptions or detailed content
  • Comments or attachments
  • Work logs or time tracking data
  • Project or board configurations
  • Other users' information beyond what you explicitly import
  • Any data unrelated to ticket linking and planning

How We Use Your Data

We use the collected information solely for the following purposes:

  • Ticket Linking: To link JIRA tickets to your pointing sessions and display ticket titles
  • Ticket Import: To allow you to import tickets from JIRA sprints into pointing sessions
  • Authentication: To authenticate API requests to JIRA on your behalf (using OAuth tokens)
  • User Identification: To identify you as the creator or participant in pointing sessions

We do not:

  • Share your data with third parties (except Atlassian/JIRA as necessary for API access)
  • Use your data for advertising or marketing purposes
  • Analyze or mine your JIRA data for any purpose beyond ticket linking
  • Access any JIRA data you haven't explicitly requested to import

Data Storage and Security

Your data is stored securely:

  • Database: User account information and OAuth tokens are stored in a secure PostgreSQL database
  • Encryption: OAuth tokens are stored encrypted (recommended for production deployments)
  • Access Control: Only authenticated users can access their own pointing sessions and imported tickets
  • Data Retention: Pointing sessions and associated data are automatically deleted after a configurable retention period (default: 14 days)

Third-Party Services

Our application integrates with Atlassian JIRA through their official OAuth 2.0 API. When you log in with JIRA:

  • Authentication is handled by Atlassian's secure OAuth service
  • We only request the minimum scopes required: read:jira-work, read:jira-user, and read:me
  • Your JIRA data remains under your organization's control and is subject to Atlassian's privacy policy
  • You can revoke access at any time through your Atlassian account settings

Your Rights

You have the right to:

  • Access: Request access to the personal data we hold about you
  • Deletion: Request deletion of your account and associated data
  • Revoke Access: Revoke JIRA OAuth access at any time through your Atlassian account settings
  • Data Portability: Export your pointing session data
  • Manual Ticket Entry: Add tickets by pasting links rather than browsing JIRA, so you can limit what we read from your JIRA site

Data Stored In Your Browser

Separately from our database, a small amount of data is kept in your own browser's local storage. It never leaves your device, is not sent to us, and you can clear it at any time through your browser settings:

  • Session Preferences: Your default estimate values, role types and QA settings, used to pre-fill the form when you create a new pointing session
  • Last Pointing Session Code: So returning to the app can take you back to the session you were last working on

Your identity is not stored in your browser. Who you are always comes from your signed-in JIRA session.

Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of any changes by posting the new Privacy Policy on this page and updating the "Last updated" date. You are advised to review this Privacy Policy periodically for any changes.

Contact Us

If you have any questions about this Privacy Policy or wish to exercise your rights, please contact us through your organization's designated channels or the application administrator.

Summary

Our Commitment:

We collect only the minimum JIRA data necessary to link tickets to your pointing sessions. We do not access, store, or process any information beyond what is required for this specific purpose. Your data is secure, and you maintain full control over your JIRA integration.